Shido Global Hack
Incident Overview
Shido Global was exploited due to a smart contract configuration error, resulting in a loss of 235,458 $USD.
Shido Global, a Cosmos-based blockchain with EVM compatibility, was exploited due to a configuration error in the lock and claim mechanism, as well as the price difference between their old and new token pools in PancakeSwap. The attacker initially took a flash loan of 40 $BNB and swapped it to obtain a large amount of Shido tokens. Then, the attacker exploited a flaw in the ShidoLock contract that allowed them to convert v1 tokens to v2 tokens at a large scale.
Finally, the exploiter swapped these tokens for 1,016 WBNB, repaid the flash loan, and made away with a profit of roughly 977 $BNB which is worth $235,458 USD. The stolen funds were transferred through Celer Bridge.
Attacker Address:
https://bscscan.com/address/0x69810917…61770d
Malicious Contract Address:
https://bscscan.com/address/0xcdb3d057…9ea4cc
Malicious Transaction:
https://bscscan.com/tx/0x72f8dd2b…a712d6
Bridging Transactions:
https://bscscan.com/tx/0x2de117d3…c8c99f
https://bscscan.com/tx/0x2a1b7601…cc69bb
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Shido Global, these are the critical security checks that could have prevented this incident (June 2023).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Shido Global
The Shido Global hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.